Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 140

Количество 373 140

nvd логотип

CVE-2005-2818

почти 21 год назад

Cross-site scripting (XSS) vulnerability in DownFile 1.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter to (1) email.php,(2) index.php, (3) del.php, or (4) add_form.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2817

почти 21 год назад

Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2816

почти 21 год назад

Cross-site scripting (XSS) vulnerability in Greymatter allows remote attackers to inject arbitrary web script or HTML via a post comment, which is recorded in a log file but not properly handled when the administrator uses "View Control Panel Log" to read the log file.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2815

почти 21 год назад

print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service (resource consumption) via an MS-DOS device name in the news parameter to print.php, such as (1) AUX, (2) CON, (3) PRN, (4) COM1, or (5) LPT1.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-2814

почти 21 год назад

Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a vis_reg operation to index.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2813

почти 21 год назад

Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) characters in the id parameter to the read mod in index.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2812

почти 21 год назад

man2web allows remote attackers to execute arbitrary commands via -P arguments.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2811

почти 21 год назад

Untrusted search path vulnerability in Net-SNMP 5.2.1.2 and earlier, on Gentoo Linux, installs certain Perl modules with an insecure DT_RPATH, which could allow local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-2810

почти 21 год назад

Multiple stack-based buffer overflows in urban before 1.5.3 allow local users to gain privileges via a long HOME environment variable to (1) config.cc, (2) game.cc, (3) highscor.cc, or (4) meny.cc.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2005-2809

почти 21 год назад

silc daemon (silcd.c) in Secure Internet Live Conferencing (SILC) 1.0 and earlier allows local users to overwrite arbitrary files via a symlink attack on the silcd.[PID].stats temporary file.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-2808

почти 21 год назад

frox 0.7.16 and 0.7.17 does not properly parse certain Deny ACLs, which might allow attackers to bypass intended restrictions and access blocked hosts.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2807

почти 21 год назад

frox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows local users to read portions of arbitrary files via the -f command line option.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2005-2806

почти 21 год назад

client.cpp in BNBT EasyTracker 7.7r3.2004.10.27 and earlier allows remote attackers to cause a denial of service (application hang) via an HTTP header containing only a ":" (colon), possibly leading to an integer signedness error due to a missing field name or value.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2805

почти 21 год назад

forum_post.php in e107 0.6 allows remote attackers to post to non-existent forums by modifying the forum number.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2804

почти 21 год назад

Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (application crash) via a large TCP/IP port in the Windows registry key.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2803

почти 21 год назад

Cross-site scripting (XSS) vulnerability in Hiki 0.8.1 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via a page name in a Login link, a different vulnerability than CVE-2005-2336.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2802

почти 21 год назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2872, CVE-2005-2873. Reason: this candidate's description originally combined two separate issues. Notes: All CVE users should consult CVE-2005-2872 and CVE-2005-2873 to determine the appropriate identifier for the issue

EPSS: Низкий
nvd логотип

CVE-2005-2801

почти 21 год назад

xattr.c in the ext2 and ext3 file system code for Linux kernel 2.6 does not properly compare the name_index fields when sharing xattr blocks, which could prevent default ACLs from being applied.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2800

почти 21 год назад

Memory leak in the seq_file implementation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows local users to cause a denial of service (memory consumption) via certain repeated reads from the /proc/scsi/sg/devices file, which is not properly handled when the next() iterator returns NULL or an error.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-2799

почти 21 год назад

Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote attackers to execute arbitrary code via a long HTTP POST request.

CVSS2: 7.5
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-2818

Cross-site scripting (XSS) vulnerability in DownFile 1.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter to (1) email.php,(2) index.php, (3) del.php, or (4) add_form.php.

CVSS2: 4.3
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2817

Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.

CVSS2: 5
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2816

Cross-site scripting (XSS) vulnerability in Greymatter allows remote attackers to inject arbitrary web script or HTML via a post comment, which is recorded in a log file but not properly handled when the administrator uses "View Control Panel Log" to read the log file.

CVSS2: 4.3
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2815

print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service (resource consumption) via an MS-DOS device name in the news parameter to print.php, such as (1) AUX, (2) CON, (3) PRN, (4) COM1, or (5) LPT1.

CVSS2: 6.4
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2814

Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a vis_reg operation to index.php.

CVSS2: 4.3
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2813

Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) characters in the id parameter to the read mod in index.php.

CVSS2: 5
7%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2812

man2web allows remote attackers to execute arbitrary commands via -P arguments.

CVSS2: 7.5
7%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2811

Untrusted search path vulnerability in Net-SNMP 5.2.1.2 and earlier, on Gentoo Linux, installs certain Perl modules with an insecure DT_RPATH, which could allow local users to gain privileges.

CVSS2: 4.6
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2810

Multiple stack-based buffer overflows in urban before 1.5.3 allow local users to gain privileges via a long HOME environment variable to (1) config.cc, (2) game.cc, (3) highscor.cc, or (4) meny.cc.

CVSS2: 7.2
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2809

silc daemon (silcd.c) in Secure Internet Live Conferencing (SILC) 1.0 and earlier allows local users to overwrite arbitrary files via a symlink attack on the silcd.[PID].stats temporary file.

CVSS2: 2.1
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2808

frox 0.7.16 and 0.7.17 does not properly parse certain Deny ACLs, which might allow attackers to bypass intended restrictions and access blocked hosts.

CVSS2: 7.5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2807

frox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows local users to read portions of arbitrary files via the -f command line option.

CVSS2: 7.2
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2806

client.cpp in BNBT EasyTracker 7.7r3.2004.10.27 and earlier allows remote attackers to cause a denial of service (application hang) via an HTTP header containing only a ":" (colon), possibly leading to an integer signedness error due to a missing field name or value.

CVSS2: 5
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2805

forum_post.php in e107 0.6 allows remote attackers to post to non-existent forums by modifying the forum number.

CVSS2: 5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2804

Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (application crash) via a large TCP/IP port in the Windows registry key.

CVSS2: 5
5%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2803

Cross-site scripting (XSS) vulnerability in Hiki 0.8.1 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via a page name in a Login link, a different vulnerability than CVE-2005-2336.

CVSS2: 4.3
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2802

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2872, CVE-2005-2873. Reason: this candidate's description originally combined two separate issues. Notes: All CVE users should consult CVE-2005-2872 and CVE-2005-2873 to determine the appropriate identifier for the issue

почти 21 год назад
nvd логотип
CVE-2005-2801

xattr.c in the ext2 and ext3 file system code for Linux kernel 2.6 does not properly compare the name_index fields when sharing xattr blocks, which could prevent default ACLs from being applied.

CVSS3: 7.5
3%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2800

Memory leak in the seq_file implementation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows local users to cause a denial of service (memory consumption) via certain repeated reads from the /proc/scsi/sg/devices file, which is not properly handled when the next() iterator returns NULL or an error.

CVSS2: 2.1
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2799

Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote attackers to execute arbitrary code via a long HTTP POST request.

CVSS2: 7.5
71%
Высокий
почти 21 год назад

Уязвимостей на страницу